Read More
Ayra WangA survey by the Office of the Privacy Commissioner for Personal Data and the Hong Kong Productivity Council Cyber Security found the Enterprise Cyber Security Readiness Index dropping to 47 points from 53.3 points out of 100.
Enterprises should raise cyber security awareness among staff after a readiness index plunged below 50 for the first time since it was launched in 2018.
ADVERTISEMENT
SCROLL TO CONTINUE WITH CONTENT
Nearly 400 enterprises were polled in September, of which a record-high 73 percent have been under at least one kind of cyber attack in the past 12 months, up 8 percent year-on-year.
Alex Chan Chung-man, general manager of digital transformation at the council, said companies need to do more to protect themselves.
"The zero-trust approach is always the number one approach when we guard against all these attacks," he said.
"There are free antivirus tools on mobile apps that can help you detect whether the links are from a malicious website.There are many ways to know whether you are encountering deep fakes, he said.
"For example, ask them to move some objects in front of their face before the camera to see any changes on the screen. If the AI algorithm is not fast enough, the face switch is not instantly reflected."Phishing attacks remained the most common, as 96 percent of companies said they had been attacked by e-mail, online advertisement counterfeiting, voice and SMS, while some reported being attacked by AI and QR code phishing. He said the drop in the index was mainly due to the loosened security risk assessment and reduced efforts in patch management measure adoption.
Corporations need to step up their employees' awareness of cyber security and organize training, Chan advised. "Humans are always the weakest link in cyber security, where many successful attacks are caused by human negligence."Privacy Commissioner for Personal Data Ada Chung Lai-ling said the risk level of using generative AI is the highest, followed by cookies.
However, only 48 percent of enterprises provided internal guidelines to address the risks arising from new technology usage.Chung urged enterprises to improvise on cyber security management, adding: "Building trust and keeping information secure is a top priority."
By the end of last month, the commissioner had received 119 data leak cases, with 30 percent from public institutions and 70 percent from private companies.Chung said her office has been working with the administration to examine the Privacy Ordinance to introduce mandatory measures, such as fines on enterprises that fail to report data leaks.
ayra.wang@singtaonewscorp.com
Ada Chung















